Android Car Systems Infected With Malware Through Software Updates

Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet.

Written By
Ken Underhill
Ken Underhill
Aug 25, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Your car’s software update is supposed to fix problems, not quietly recruit its infotainment system into a botnet.

Kaspersky publicly disclosed the campaign on Aug. 21 after its researchers uncovered malware spreading through the legitimate update mechanism used by some Android-based car head units. The malware can be installed on affected infotainment systems without requiring drivers to install anything, and then used to commit ad fraud and as part of a proxy botnet.

Kaspersky’s findings suggest the issue is limited to specific Android-based head units, not to Android Auto or Android-powered vehicles as a whole. Researchers traced the campaign to head units via software from the Chinese automotive technology provider DoFun, which used compromised update channels to deliver malware.

Malware arrives through a legitimate update app

Kaspersky researchers discovered the campaign in June while investigating an unusual Android application called JarService. Unlike typical Android malware, it had no user interface and did not rely on tricking users into installing it because it was already embedded in the head unit’s firmware. 

JarService was delivered through TWCore, a legitimate system application that manages software updates on affected DoFun head units. Attackers abused this trusted update channel to distribute malware without requiring any user action. 

Kaspersky described the campaign as the first documented case of malware delivered to automotive head units via an automated firmware update service. DoFun told Kaspersky that the issue responsible for the distribution of malicious software has since been fixed.

The attack resembles a broader security problem enterprises have confronted with other trusted software channels. Earlier this year, attackers hijacked the Notepad++ update infrastructure to distribute malicious installers, demonstrating how a standard update process can become an attack vector when its underlying infrastructure is compromised.

Advertisement

Infected cars become part of a proxy botnet

JarService is only the first stage.

Once installed, the malware decrypts and launches another loader that contacts an attacker-controlled command-and-control server to retrieve additional payloads. One of those payloads can generate fraudulent advertising activity, while the other can add the infected head unit to a proxy network.

According to Kaspersky’s analysis of the campaign, infected systems can send information including their device model, screen resolution, MAC address, and connected Wi-Fi network to the attackers. The malware can receive commands to make HTTP requests, open webpages, and download and execute additional malicious code.

Researchers linked the activity to MoYu Group, a threat actor associated with the BADBOX malware ecosystem. Kaspersky also found links between MoYu Group and residential proxy services that allow customers to route internet traffic through devices connected to the botnet.

That means the target is not necessarily the data stored in the car. The vehicle itself becomes valuable infrastructure.

Android’s flexibility helps manufacturers build highly customized infotainment systems, but it also gives attackers another familiar operating environment to target. Mobile threats have already pushed well beyond conventional malicious apps. The recently discovered Manic Android malware can relay stolen information through nearby infected phones, while Google has also had to patch Android vulnerabilities already being exploited in attacks.

What drivers and security teams should know

Kaspersky found no evidence that the malware could control critical vehicle functions such as steering, braking, or acceleration. The campaign targeted Android-based infotainment head units and used their internet connections for malicious activity. 

The impacted systems also represent only a subset of the automotive market. DoFun develops firmware, applications and cloud services for Android-based automotive head units and says its products serve more than 30 million vehicle owners worldwide, but Kaspersky has not said that all of those devices were compromised.

Advertisement

This attack shows how weaknesses in the software supply chain can extend to connected vehicle systems. 

Modern vehicles rely on internet-connected hardware, third-party software, and automated updates, increasing the overall attack surface area. Security teams managing vehicle fleets should include infotainment and other connected systems in asset inventories, network monitoring, and third-party risk assessments. 

For drivers, unexpected apps or unusual network activity on an Android-based head unit should be treated as potential signs of compromise. 

As more vehicle systems become connected, manufacturers and fleet operators need to account for the security risks that come with third-party software and update mechanisms. The DoFun campaign shows how compromising one of those trusted channels can turn vehicle hardware into part of a botnet. 

Also read: Manic Android malware can steal banking credentials and relay stolen data through nearby infected phones, showing how mobile threats are finding new ways around traditional defenses.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.